Dropped Files | ZeroBOX
Name 6760ccf00dfff216_xrlrshqq.dll
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\nsnF34B.tmp\xrlrshqq.dll
Size 41.0KB
Processes 2680 (lsass.exe)
Type PE32 executable (DLL) (console) Intel 80386, for MS Windows
MD5 0177e50467e101a4516842e99de1b197
SHA1 96972bdf37d92630bcdae67390657d0173e6103b
SHA256 6760ccf00dfff216aa5ff6815aaa1cecdfaa16d65f378af8166ce638ea655081
CRC32 77A3C20A
ssdeep 768:6n09JsJNJ4PwonAUSFoxObYkjExbaNKoWRm2Ua6WNe:vJMNEwonlSQiWmkNNe
Yara
  • UPX_Zero - UPX packed file
  • OS_Processor_Check_Zero - OS Processor Check
  • IsDLL - (no description)
  • Malicious_Library_Zero - Malicious_Library
  • PE_Header_Zero - PE File Signature
  • IsPE32 - (no description)
VirusTotal Search for analysis
Name b6d717d453b8c088_sfbrfzarzi.n
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\sfbrfzarzi.n
Size 5.6KB
Processes 2680 (lsass.exe)
Type data
MD5 ff60faa65c246551e9b0c2dd41ecfae8
SHA1 dda2dca4d062a7a87ab5122aabb5a94d37babdf2
SHA256 b6d717d453b8c0880b62a045ab7847c79e8c50770e73593006690d9eec9c358e
CRC32 75D163E3
ssdeep 96:8UfTtXiAlVO0aQliL+dlaGTCUmNvWXNplu6LQ+CBPy5qe16t+NLvDGwv:tTtXiA3qclafp18u60+CBPyKt+VDGwv
Yara None matched
VirusTotal Search for analysis
Name 6ef07b5649e198f5_trjxnoxcblo.cv
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\trjxnoxcblo.cv
Size 206.0KB
Processes 2680 (lsass.exe)
Type data
MD5 85a7a8065e4f02eda7499298b0e8c640
SHA1 a245d33e76d47621ba86982e016db3f9723ad6d8
SHA256 6ef07b5649e198f5bd9bc7b23c845e15bd66ac09361eeac870de0fb2d262cd09
CRC32 B595F100
ssdeep 6144:4VJF5D2v/IP7m5F+TeFQMxq2dds06IqghMLvw4N:4VJF5n65F+g5qCs06IqgiLvR
Yara None matched
VirusTotal Search for analysis
Name e3b0c44298fc1c14_nsxF2EB.tmp
Empty file or file not found
Filepath C:\Users\test22\AppData\Local\Temp\nsxF2EB.tmp
Size 0.0B
Type empty
MD5 d41d8cd98f00b204e9800998ecf8427e
SHA1 da39a3ee5e6b4b0d3255bfef95601890afd80709
SHA256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
CRC32 00000000
ssdeep 3::
Yara None matched
VirusTotal Search for analysis